Live data from Hacker News

Mozilla’s DNS over HTTPs

blog.mozilla.org

301–310 of 777 posts

Re: Mozilla’s DNS over HTTPs

#301

Earlier quoted context omitted.

So what if I run a Pihole at home as a DNS server and want to stop being able to resolve various domains? I would like to know how to stop all devices (actually worse, individual applications!) on my network deciding to DoH of their own accord (and therefore bypassing my local DNS server). This kind of centralised ability to block DoH is very useful to me.

Of note: PiHole supports DoH, so you point your DoH supporting applications at it. If your OS gets around to adding DoH support you can point your entire OS at it and disable DoH in applications, but until then you'll have to do things the hard way.

At present though devices on the network all for DNS and my network says "use pihole" but applications that implement DoH never ask the network, so I have to have access to all the applications (including those from bad actors).

I block MS telemetry domains for example, where's the config for me to stop them using DoH; what about the trackers on my TV?

Now I need to configure every device - that's capable of using Firefox - rather than configuring the network. Presumably in short shrift there'll be no way to block Google advertising. I guess Google will get their return on funding Firefox.

Re: Mozilla’s DNS over HTTPs

#303

Seems very marginal for privacy when people in the middle can still see the IP you're connecting to, just not which DNS record you may have retrieved the IP with.

It's far easier for ISPs to scrape up your DNS queries (they run the resolver) than it is for the to make correlations based on IP addresses, especially with multiple websites hosted on the same IP.

Soon to be resolved by IPv6 everywhere.

Re: Mozilla’s DNS over HTTPs

#304
post #121

Earlier quoted context omitted.

So what if I run a Pihole at home as a DNS server and want to stop being able to resolve various domains? I would like to know how to stop all devices (actually worse, individual applications!) on my network deciding to DoH of their own accord (and therefore bypassing my local DNS server). This kind of centralised ability to block DoH is very useful to me.

There are a couple use-cases here. * On devices that you own and control you don't need a network level control like this except for convenience. This is when you should be applying the override record. * On devices that you do not own or control (family/friends/guests) disabling DoH makes you the malicious network operator. Connecting to your Wi-Fi doesn't make you trusted in any sense of the word. * On devices that…

I'm _maliciously_ stopping my kids Android apps from connecting to tracking and malware domains. What a tyrant I am - I should have over control to a third-party for profit company??!?

You're kidding, right.

Re: Mozilla’s DNS over HTTPs

#305

I wish they wouldn't do this. I trust my ISP more than I trust Firefox and whatever company they chose for DNS over HTTP. This "We know better than you" attitude is why I stopped using Firefox so many years ago. I switched back recently, to stop using Chromium, but I have a growing list of annoyances, and it might be time to give NeXt Browser a chance again, or see what else is out there.

"Firefox defaults to Cloudflare, though you can change this."

So it's whichever company you choose for DNS, rather than the company chosen by your ISP. Many of us were already choosing not to use the ISP's DNS, for reliability, but with this feature the ISP can't eavesdrop on that.

Re: Mozilla’s DNS over HTTPs

#306

Can you disable this?

What are some reasons why someone would prefer to or need to disable it. Just curious.

It's essentially the same question as "why would you choose another DNS server?"

There are numerous other options like Google, Quad9, OpenDNS, OpenNIC, DNSWatch or Verisign, each of which have pros and cons like speed, privacy, reliability or accuracy. Many people also use VPNs which provide DNS servers that are perceived to increase privacy.

I know this is currently US only but were it to roll out worldwide, personally I'm in a country with strong legal privacy protections and trust my ISP far more than any American company.

Re: Mozilla’s DNS over HTTPs

#309

Earlier quoted context omitted.

I know Brave is supposed to be a privacy-centric browser, but their plan for advertising seems at odds with that. Advertising is a slippery slope and I wonder how long before these promises are eroded or outright reversed. > 100% of your ad spend is placed for active users that opt-in to a rewarding private ad experience. > Craft effective offers and provide captivating full-page experiences directly with consumers i…

I think the only reason Brave wasn't immediately laughed out of the room on HN as a browser that literally shows you its own ads is because they brilliantly have their own cryptocoin (BAT) so that anyone who thinks their $10 investment will buy them a lambo one day will come out of the woodwork to mention the browser. The same thing you saw happen to any other cryptocurrency. It basically kills all earnest conversati…

BAT is necessary in order to allow decentralized payments from users to site operators with no intermediary. No centralized alternative system would be sufficient for Brave's use-case.

Re: Mozilla’s DNS over HTTPs

#310
post #54

If you are a network administrator and want none of this, look at that: https://support.mozilla.org/en-US/kb/canary-domain-use-appli... Basically, make use-application-dns.net. return an error (any kind will do). Filter it in your recursor for example. Having the browser change a fundamental behaviour that used to stand for decades is highly problematic. If nothing else, it is the network administrator who should hav…

I'd guess that the overwhelming majority of Mozilla's users do not have a "network administrator" looking after issues like this for them. All they have is an ISP, and the ISP is not on the user's side.

The ISPs can easily be swapped out, they're was much on the client side as Cloudflare, probably more so.
Post reply on HN